PT-2020-15030 · Apache · Apache Airflow

Ali Al-Habsi

·

Published

2020-12-11

·

Updated

2024-03-06

·

CVE-2020-17515

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Apache Airflow versions prior to 1.10.15
Description The issue is related to an XSS exploit through the origin parameter passed to certain endpoints, such as '/trigger'.
Recommendations For versions prior to 1.10.15, update to version 1.10.15 or later to resolve the issue. As a temporary workaround, consider restricting access to the vulnerable endpoint '/trigger' until a patch is available. Avoid using the origin parameter in the affected API endpoint until the issue is resolved.

Fix

XSS

Weakness Enumeration

Related Identifiers

BIT-AIRFLOW-2020-17515
CVE-2020-17515
GHSA-86VP-X3PR-79RX
PYSEC-2020-21

Affected Products

Apache Airflow